cbcvebase.
CVE-2022-46705
published 2023-02-27

CVE-2022-46705: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2…

PriorityP179medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.97%
57.7th percentile
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, Safari 16.2. Visiting a malicious website may lead to address bar spoofing.

Affected

19 ranges
VendorProductVersion rangeFixed in
appleios_15.7.2_and_ipados
appleios_16.2_and_ipados
appleios_16.4_and_ipados
appleipados< 15.7.215.7.2
appleipados>= 16.0 < 16.216.2
appleiphone_os< 15.7.215.7.2
appleiphone_os>= 16.0 < 16.216.2
applemacos< 13.113.1
applemacos>= unspecified < 13.113.1
applemacos>= unspecified < 16.216.2
applemacos_ventura
applesafari< 16.216.2
applesafari
appletvos< 16.216.2
appletvos16.2
applewatchos< 9.29.2
applewatchos
debianwebkit2gtk< webkit2gtk 2.38.4-1 (bookworm)webkit2gtk 2.38.4-1 (bookworm)
debianwpewebkit< webkit2gtk 2.38.4-1 (bookworm)webkit2gtk 2.38.4-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability involves improper handling of URLs in WebKit, enabling address bar spoofing. Detection should focus on suspicious URL patterns or navigations that result in a mismatch between the displayed URL and the actual loaded resource.
  • Affected components are WebKit-based browsers (Safari, WebKitGTK). Monitor for user visits to crafted websites that manipulate the address bar display, particularly on unpatched iOS/iPadOS < 16.2, macOS Ventura < 13.1, Safari < 16.2, and iOS/iPadOS < 15.7.2.
  • WebKitGTK on Linux (Red Hat Enterprise Linux 6/7) is also affected. Monitor for exploitation attempts targeting WebKitGTK-based applications where a remote attacker may bypass security restrictions via specially crafted URLs.
  • ·WebKitGTK packages on Red Hat Enterprise Linux 6 and 7 are out of support scope, meaning no patches will be provided by Red Hat for these versions.

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
osv4.3MEDIUM
vulncheck4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.